CVE-2005-0711
LOW severity · CVSS 2.1
2.1CVSS LOW
Summary
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)2%
AV:L/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml ↗
Additional information
- NVD record
- http://www.gentoo.org/security/en/glsa/glsa-200503-19.xmlPatch
- http://www.novell.com/linux/security/advisories/2005_19_mysql.htmlPatch
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:060
- http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0082.htmlExploit
- http://www.debian.org/security/2005/dsa-707Exploit